what are your symptoms? Enable logging on the rule and check the firewall logs -- maybe the rule is working and the problem is on 10.0.1.4.
Is 10.0.1.4 OK to NAT out the same pfsense gateway now? (10.0.1.4 outbound NAT'ed and routed correctly?) Is 10.0.1.4 listening/accepting on 80 for internal hosts? Do you really need external interface (any)? Can you specify a single IP address externally (interface address or Virtual IP). Gordon Russell Clarke County IT ----- Original Message ----- From: "Jeremy Bennett" <jbenn...@hikitechnology.com> To: support@pfsense.com Sent: Friday, September 3, 2010 2:42:28 PM Subject: [pfSense Support] Simple? NAT question PFSense 1.2.3 Embedded Release on an Alix 2c3 Local network is 10.0.1.x subnet Trying to get port forwarding setup so that inbound connections on static public IP/WAN/port 80 get forwarded to LAN 10.0.1.4 Went to NAT > Port Forward and Setup a new rule that says: If - Proto - Ext. port range - NAT IP - Int. port range - Description WAN - TCP/UDP - 80 (HTTP) - 10.0.1.4 - (ext.: any) - 80 (HTTP) - WAN to 10.0.1.4 I let the NAT rule creation create the following Firewall rule: Proto - Source - Port - Destination - Port - Gateway - Schedule - Description TCP/UDP - * - * - 10.0.1.4 - 80 (HTTP) - * - none - NAT 80 to 10.0.1.4 This is driving me batty. I've setup NAT before and never run into any problems-I've compared this attempt to known good configs, as well as searched the message boards with no luck. I've already swapped out the hardware to try and rule that out. There aren't any other rules configured other than the defaults, and the only thing that this box is doing is being a router and pptp vpn server. Any help is appreciated. --------------------------------------------------------------------- To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org --------------------------------------------------------------------- To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org